Categories: Ransom

What is “Ransom:Win32/Genasom”?

The Ransom:Win32/Genasom is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Genasom virus can do?

  • Creates RWX memory
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

How to determine Ransom:Win32/Genasom?


File Info:

crc32: B3ED9540md5: 10bc8a66ffe85a5eb04d5dd463204318name: WinLocker-Builder.exesha1: e0df54485e4fba5af4ff0a61c022f794a5ba25d1sha256: 3def8e9db50996046391a345099f3f7b023f8e0e26356702f73743e25d5716f8sha512: 3d833e8083cb4e781b7572eedc89d4c94ea91a04a77f0e7727ff8bb4d16bb8887c19b6a2470e90a2cf714bdf72d26679075f7c7f4127e1c504182955808b99e8ssdeep: 6144:eUKmfbTAYbMLaOphVx4bu9xJjF1031CP82ooSaYq:eUvfHfMLaOpXKbOjj/sNLoSbqtype: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: InternalName: FileVersion: 0.2.0.0CompanyName: VAN32LegalTrademarks: Comments: ProductName: ProductVersion: 0.2.0.0FileDescription: WinLocker BuilderOriginalFilename: Translation: 0x0419 0x04e3

Ransom:Win32/Genasom also known as:

MicroWorld-eScan Trojan.Generic.7992186
FireEye Trojan.Generic.7992186
CAT-QuickHeal TrojanRansom.Blocker
McAfee Generic.dx!10BC8A66FFE8
Cylance Unsafe
VIPRE Trojan.Win32.Generic!BT
K7AntiVirus Trojan ( 7000000f1 )
BitDefender Trojan.Generic.7992186
K7GW Trojan ( 7000000f1 )
Cybereason malicious.6ffe85
BitDefenderTheta Gen:NN.ZelphiF.34090.tmKfaGQ!m2kk
Symantec ML.Attribute.HighConfidence
ESET-NOD32 Win32/LockScreen.AFL
Baidu Win32.Trojan.LockScreen.bk
TrendMicro-HouseCall TROJ_RANSOM.SMC1
Avast Win32:Dropper-gen [Drp]
ClamAV Win.Trojan.Scar-8454
GData Trojan.Generic.7992186
Kaspersky Trojan-Ransom.Win32.Blocker.hnwj
Alibaba Ransom:Win32/Blocker.1c7ff9f7
NANO-Antivirus Trojan.Win32.Winlock.bqdzr
AegisLab Trojan.Win32.Blocker.4!c
Rising Ransom.Blocker!8.12A (CLOUD)
Ad-Aware Trojan.Generic.7992186
Sophos Troj/Agent-AONU
Comodo Malware@#31gkmalbfnlt4
F-Secure Trojan.TR/Rogue.325120
DrWeb Trojan.Winlock.2959
Zillya Dropper.Agent.Win32.57552
TrendMicro TROJ_RANSOM.SMC1
McAfee-GW-Edition BehavesLike.Win32.Gnamer.fc
Emsisoft Trojan.Generic.7992186 (B)
Jiangmin TrojanDropper.Agent.atjw
Avira TR/Rogue.325120
Antiy-AVL Trojan[Ransom]/Win32.Birele
Endgame malicious (high confidence)
Arcabit Trojan.Generic.D79F37A
AhnLab-V3 Trojan/Win32.Birele.C957512
ZoneAlarm Trojan-Ransom.Win32.Blocker.hnwj
Microsoft Ransom:Win32/Genasom
TotalDefense Win32/Ransom.AWS
ALYac Trojan.Generic.7992186
MAX malware (ai score=100)
VBA32 Hoax.Birele
Panda Generic Malware
Tencent Malware.Win32.Gencirc.10b1a9c6
Yandex Trojan.DR.Agent!PM89YJOqyD0
Ikarus Trojan.Win32.Scar
Fortinet W32/Agent.DRQL!tr
Webroot W32.Trojan.Ransom.CN
AVG Win32:Dropper-gen [Drp]
CrowdStrike win/malicious_confidence_60% (W)
Qihoo-360 Win32/Trojan.Ransom.6a5

How to remove Ransom:Win32/Genasom?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

How to remove “Worm:Win32/Korgo.V”?

The Worm:Win32/Korgo.V is considered dangerous by lots of security experts. When this infection is active,…

11 mins ago

Worm.Win32.Vobfus.dlcn (file analysis)

The Worm.Win32.Vobfus.dlcn is considered dangerous by lots of security experts. When this infection is active,…

15 mins ago

Win32/Adware.InternetAntivirus removal instruction

The Win32/Adware.InternetAntivirus is considered dangerous by lots of security experts. When this infection is active,…

15 mins ago

TrojanDownloader:Win32/Unruy.A removal instruction

The TrojanDownloader:Win32/Unruy.A is considered dangerous by lots of security experts. When this infection is active,…

20 mins ago

Trojan:MSIL/Zusy.RDF!MTB removal guide

The Trojan:MSIL/Zusy.RDF!MTB is considered dangerous by lots of security experts. When this infection is active,…

20 mins ago

About “Win32:Sality-KYG” infection

The Win32:Sality-KYG is considered dangerous by lots of security experts. When this infection is active,…

20 mins ago